Skip to main content

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

Attribute-Based Access Control: How ABAC Works in the OneTrust Platform

ABAC helps security teams manage record-level access with more precision.  

Abbey Wolfe
OneTrust Platform Product Manager
August 11, 2026

Five professionals meet around a table reviewing documents, laptops, and tablets in a modern office space.

Attribute-based access control (ABAC) helps teams grant the right people access to the right records without overbroad permissions.

A familiar access problem shows up in almost every growing governance program.

A security administrator gets a request from someone who needs access to one specific record: one assessment for legal review, one policy for approval, one vendor record for onboarding, or one AI model for cross-functional input. The ask is narrow, but the access options are often broad. Too often, the choice becomes granting a wider role than the situation requires or creating another exception that adds complexity to the environment.

That is why ABAC matters.

If you're responsible for administering access, supporting governance workflows, or reducing operational risk, ABAC adds precision. It helps teams collaborate on the records they need without opening access more broadly than intended. For managers and the CISO office, it offers a practical way to support least-privileged access while keeping work moving.

In OneTrust, ABAC currently supports record-level access control. It complements role-based access control (RBAC), which continues to serve its own baseline permission use cases. ABAC adds another layer of control by determining which specific records those permissions should apply to.

 

What Is ABAC?

At a practical level, ABAC adds record-level control in the OneTrust AI-Ready Governance PlatformTM. Instead of granting broad access to every assessment, policy, vendor, or AI model, ABAC allows granting access to the specific records they need.

That matters because governance workflows often involve temporary approvers, regional stakeholders, business owners, legal reviewers, security teams, and external collaborators. In those moments, ABAC provides a more targeted way to enable work without expanding access beyond what is necessary.

The foundation centers on five capabilities: direct sharing, request access, assignments, manage access, and auditing.

 

How ABAC Works

The core concept is the assignment. An assignment defines what a user can do with a record, including actions such as viewing, editing, commenting, completing tasks, sharing, or managing access.

Access can be granted in three main ways:

  • Direct sharing: A user with the right permissions can share a specific record with another user and define the assignment that person should receive.
  • Record attributes: For example, if a business owner is associated with a record, that relationship can determine their access to it. This is what makes ABAC valuable in practice: access is tied to context, not just to a static role.
  • Workflows: An admin can set up a workflow to automatically share an assignment with a user identified in that workflow. For example, a user added as a risk approver via workflow automation would automatically be assigned to the workflow, enabling them to access the created risk.

 

OneTrust Third-Party Risk Management Engagements page showing a list of third-party engagements. The options menu for “Engagement name 2” is open, with “Share” at the top, followed by options to launch an assessment, change status, export as PDF, reassign the engagement, or delete it.

Engagements Sharing in Third-Party Management

 

ABAC also supports the operational side of access control. Users can request access to a record. Record owners or administrators can approve or deny those requests. Access can be reviewed or revoked later. Auditing helps capture who granted access, to which record, and when.

 

Practical Use Cases Across OneTrust Solutions

In AI Governance, a team may need a privacy stakeholder to review one specific AI model. ABAC allows that model to be shared for the task without exposing a broader set of AI records, and access can be removed when the review is complete.

In Privacy Automation, ABAC supports targeted access to assessments and processing activities. A legal reviewer may need read-only access to a single assessment, or a business owner may need visibility into a specific processing activity they are responsible for, without receiving broad access to the full data map.

In Tech Risk and Compliance, ABAC can reduce role complexity when a CISO or regional stakeholder needs to review a specific policy, risk, or issue. Rather than assigning a wider standing role, teams can grant access only to the relevant record.

In Third-Party Management, ABAC supports more targeted collaboration around vendor and engagement records. A specific engagement can be shared with the right internal stakeholder, or a vendor contact can request access to their own record to support onboarding or related activities.

 

What This Means for Practitioners

For security administrators, the value is straightforward: fewer broad-role exceptions, better control over who can access which records, and a cleaner way to support cross-functional work. For managers, it helps teams move faster without sacrificing governance discipline. For the CISO office, it supports a more defensible least-privilege posture with stronger auditability around access decisions.

It's also important to understand that ABAC doesn't automatically clean up existing access models. Teams still need to define assignments thoughtfully, decide who should be able to share or approve access, and align access design to the workflows they are trying to support.

Done well, ABAC helps organizations add flexibility to their access model without losing control.

Register to attend the Introduction to OneTrust Attribute-Based Access Control webinar

 

Frequently Asked Questions

 

Attribute-based access control, or ABAC, is a record-level access model that helps organizations decide who should be able to access specific records and what they should be able to do with them.

RBAC is used for baseline permissions. ABAC complements that model by adding more precise control over which individual records those permissions apply to.

ABAC is especially useful when access requests are narrow, temporary, cross-functional, or difficult to manage through broad-standing roles alone.

ABAC helps teams grant access only to the records required for a task, rather than expanding access across a wider object, workflow, or organization.

The strongest examples include AI Governance, Privacy Automation, Tech Risk, and Third-Party Management workflows, in which multiple stakeholders require targeted access to specific records.